CORE IMPACT v7.5 - Exploits Update (Tue Apr 22 2008)
SurgeMail Mail Server Exploit update
Exploits/Remote [Windows]
Tue Apr 22 2008
This module exploits a buffer overflow in SurgeMail Mail Server and installs an agent into the target host. A buffer overflow vulnerability is located in the function which handles the real CGI executables. This can be exploited to cause a stack-based buffer overflow via an overly long, specially-crafted argument passed to this module. This exploit perform three attempts to disable DEP in XP SP2 and Windows 2003.
Exploits Vulnerabiltiy: CVE-2008-1054











